Vulnerability Description
The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackmagicdesign | Web Presenter Hd Firmware | 3.3 |
| Blackmagicdesign | Web Presenter Hd | - |
Related Weaknesses (CWE)
References
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-5743ExploitThird Party Advisory
- https://www.blackmagicdesign.com/Product
FAQ
What is CVE-2025-57437?
CVE-2025-57437 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuratio...
How severe is CVE-2025-57437?
CVE-2025-57437 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-57437?
Check the references section above for vendor advisories and patch information. Affected products include: Blackmagicdesign Web Presenter Hd Firmware, Blackmagicdesign Web Presenter Hd.